Your review has been sent successfully

Jenkins Update

3133
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

24 December, 2019

● Medium

2019-760

All

Description:

Jenkins has released an update to address multiple vulnerabilities in the following system versions:

  • Alauda DevOps Pipeline Plugin
  • Weibo Plugin
  • Build Failure Analyzer Plugin
  • buildgraph-view Plugin
  • Gerrit Trigger Plugin
  • Mantis Plugin
  • Maven Release Plug-in Plugin
  • Mission Control Plugin
  • Pipeline Aggregator View Plugin
  • RapidDeploy Plugin
  • Redgate SQL Change Automation Plugin
  • Rundeck Plugin
  • SCTMExecutor Plugin
  • Spira Importer Plugin
  • Team Concert Plugin
  • WebSphere Deployer Plugin
  • Alauda Kubernetes Suport Plugin

Threats:

An attacker could exploit these vulnerabilities by doing the following:

  • Man-in-the-Middle
  • Cross-Site Scripting
  • Cross-site request forgery (CSRF)
  • Obtain Sensitive information

Best practice and Recommendations:

The CERT team encourages to update the affected versions according to the links below:

https://jenkins.io/security/advisory/2019-12-17/

Last updated at 7 January, 2020

Rate the content

rate-icon
up icon